CVE-2020-26144
⚪ Do wiadomości
Luka w Samsung Galaxy S3 pozwala na wstrzykiwanie dowolnych pakietów sieciowych.
CVSS
6.5
EPSS
4.9%
Exploit
none
Vendor
arista
Opis źródłowy (NVD)
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 4.9% |
| Opublikowano (NVD) | 2021-05-11 20:15:08 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:16:58 UTC |
Referencje
- http://www.openwall.com/lists/oss-security/2021/05/11/12 ([email protected]) [Mailing List, Third Party Advisory]
- https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdf ([email protected]) [Third Party Advisory]
- https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md ([email protected]) [Third Party Advisory]
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu ([email protected]) [Third Party Advisory]
- https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63 ([email protected]) [Third Party Advisory]
- https://www.fragattacks.com ([email protected]) [Third Party Advisory]
- https://cert-portal.siemens.com/productcert/html/ssa-019200.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)
- https://cert-portal.siemens.com/productcert/html/ssa-913875.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)